Upwind Security
Runtime-first cloud and AI security platform — valuation re-rated 2.5x in eight months as the Israeli-founded challenger steps into the vacuum left by Wiz’s exit to Google
Upwind Security Inc. is a runtime-first cloud-native application protection platform (CNAPP) vendor founded in San Francisco in 2022. From an underwriting standpoint, the defining feature of the cap table is management quality: the entire founding bench is a repeat team with a prior nine-figure exit and shared operational history at Israel’s Unit Mamram. Headquarters sit in San Francisco, with a dual-hub structure extending to Tel Aviv, the UK, and Iceland.
Shachar’s career began in the IDF’s Mamram unit, where he served as Linux Kernel team lead from 2008 to 2012 before spending six years as an officer overseeing the military’s data-center infrastructure and leading its first VMware virtualization deployment. Following a stint as DevOps Director at Ybrant Digital (2012–2014), he founded Spot.io (originally Spotinst) in 2015 out of a college capstone project. Spot.io built reserved- and spot-instance optimization technology that cut customers’ cloud compute bills by as much as 80%, scaling to roughly 200 employees across Tel Aviv, London, and San Francisco before its 2020 sale to NetApp for $450 million. Shachar remained at NetApp as VP & General Manager of the Spot business unit through 2022 — a tenure in which he witnessed firsthand how security teams flagged findings without the operational context to act on them. That structural gap is the direct thesis behind Upwind.
A Spot.io founding team member who now owns Upwind’s technical architecture, leading development of the eBPF-based runtime sensor layer and the Neo4j asset relationship graph at the core of the platform.
Both carried over from the original Spot.io founding bench. Ferdman currently leads Growth, while both were central to early product and organizational build-out.
Upwind competes in the CNAPP category, consolidating posture management, workload protection, detection and response, and identity security into a single platform. Its principal differentiator is what the company calls the “Security Runtime Fabric” — an eBPF-based live telemetry layer paired with a Neo4j asset relationship graph, designed to reconstruct attack paths from observed behavior rather than static configuration snapshots.
Module Architecture: Upwind’s CNAPP ships the following capabilities on a single dashboard, and the company’s central sales pitch is “runtime-verified” risk prioritization versus static-scan-only incumbents.
Kernel-level eBPF sensors and serverless tracers capture live process, network, and syscall data, correlated against cloud activity logs to reconstruct multi-step intrusion paths — an infrastructure investment that static-scan competitors cannot replicate quickly.
Launched December 2025, this integrated suite detects anomalous behavior across LLM, agent, and MCP infrastructure — including prompt injection and jailbreak attempts across Layers 3, 4, and 7 — and delivers a real-time inventory of AI models, frameworks, and agents.
Released April 2025, the posture-management engine graphs how risks combine in practice using behavioral data rather than static config values, with an integrated Attack Surface Management module simulating the external attacker’s vantage point.
Nvidia Joint Research: Through a joint security research initiative with Nvidia, Upwind claims its technology detects malicious prompts targeting LLMs with approximately 95% precision while maintaining real-time performance. Analysts should note this is a company-disclosed figure without independent third-party benchmark verification.
Customer Base: The company cites Siemens, Peloton, Roku, Wix, Nextdoor, and Nubank among its logos, spanning mid-market to enterprise cloud-native organizations. The hire of Rinki Sethi — formerly CISO at Bill.com — as Chief Security Officer is a further credibility marker within the buyer community. Specific customer counts and revenue concentration remain undisclosed.
Upwind has raised in excess of $680 million in just under four years, with valuation re-rating from $1.5 billion in January 2026 to $3.8 billion by September 2026 — a 2.5x-plus step-up in eight months that ranks among the steepest of the current cycle. The timing coincides closely with Google’s March 2026 close of its $32 billion Wiz acquisition, which removed the category’s largest independent platform and, per most press coverage, concentrated growth capital on the remaining standalone CNAPP leaders.
Raised in stealth shortly after founding, co-led by Greylock Partners, which characterized it as the largest seed round it had participated in for a software company — citing both the urgency of the runtime cloud security problem and the founders’ proven exit history (Spot.io / NetApp, $450M). Cyberstarts and Leaders Fund co-invested.
A follow-on round closed eleven months after founding, reportedly at roughly 3x the seed valuation (per unconfirmed press reporting; no official figure disclosed). Proceeds funded early-stage scale-up, taking headcount from 30 to 80. Craft Ventures, Cerca Partners, Steph Curry’s Penny Jar Capital, and Omri Casspi’s Sheva participated alongside existing backers.
Led by Craft Ventures with TCV and Alta Park Capital joining as new investors, closed after Upwind had signed “dozens” of Fortune 500 logos and scaled to roughly 160 employees. Proceeds funded R&D and a net headcount addition of around 100 across Israel, San Francisco, and Iceland. Separately, Datadog was reported to have explored a roughly $1 billion acquisition of Upwind in 2025; no transaction materialized (unconfirmed, sourced to unnamed parties).
Led by Bessemer Venture Partners, with Salesforce Ventures and Picture Capital joining as new investors, taking cumulative funding to $430 million. Management cited roughly 900% year-over-year revenue growth and 200% logo growth versus the prior round — company-disclosed figures, not drawn from audited financial statements. Proceeds were earmarked to extend the CNAPP into data and AI security.
Salesforce Ventures reportedly invested an additional tens of millions of dollars at a $1.6 billion mark. No official round label has been confirmed; the transaction reads as a valuation step-up within the Series B window rather than a distinct priced round.
Round Characteristics: Co-led by Bessemer Venture Partners and TCV, with Craft Ventures, Salesforce Ventures, Greylock, Cyberstarts, Leaders Fund, and Alta Park Capital returning as follow-on participants. The step-up from the $1.5B January mark represents an approximate $2.3B (+153%) valuation increase, taking cumulative funding above $680 million.
Financial Context (Unconfirmed Estimates): ARR reportedly sat below $20 million at year-end 2025 and has since climbed to an estimated $50–60 million by mid-2026, with management guiding to $100 million ARR by year-end. These figures are unaudited third-party estimates; the implied ARR multiple — roughly 65x–190x depending on which ARR estimate is applied — sits at the aggressive end of the current cybersecurity growth cohort.
Market Context: Google’s completion of its $32 billion Wiz acquisition in March 2026 removed the category’s largest independent platform from the field. Multiple outlets frame the resulting capital concentration on remaining standalone leaders — Upwind chief among them — as a primary driver of this round’s pricing.
The November–December 2024 $100M round carries inconsistent labeling across sources: TechCrunch (Nov. 8, 2024) characterizes it as “Series B,” while Upwind’s own blog and certain data vendors label it “Series A.” Official round lettering does not reconcile cleanly across these sources. The subsequent January 2026 $250M round, by contrast, is consistently labeled “Series B” by both the company and press — this report follows the company’s most recent official designation. ARR figures, headcount, and the reported Datadog acquisition talks are all sourced to unnamed-party press reporting and should not be treated as audited financial disclosure.
Upwind’s moat rests on four pillars: (1) an eBPF sensor and graph infrastructure that static-scan incumbents cannot replicate on short notice; (2) capital-market credibility earned by a proven, repeat founding team; (3) a category vacuum created by Wiz’s exit to Google; and (4) an emerging AI security expansion vector. Investors should weigh that a meaningful portion of this moat remains a thesis rather than a revenue-scale-proven advantage.
The combination of eBPF-based runtime sensors and a Neo4j asset relationship graph delivers live execution context that agentless competitors in the Wiz/Orca mold structurally lack. Sensor-deployment friction — customers’ well-documented reluctance to install agents — is real, but it is a barrier that cuts against new entrants just as much as it does against Upwind.
CEO Shachar and his co-founders’ shared history building and exiting Spot.io gave Upwind unusually rapid access to top-tier capital — Greylock, Bessemer, and TCV among them — despite an early-stage revenue base. That is a genuine speed-to-capital advantage, but it also means a meaningful “founder premium” is embedded in the current valuation, warranting scrutiny of how much of the multiple is fundamentals versus pedigree.
Google’s March 2026 close of its $32 billion Wiz acquisition folded the category’s largest independent CNAPP vendor into a hyperscaler, generating incremental demand among buyers who prize multicloud neutrality. Market consensus positions Upwind as one of the most direct beneficiaries among the remaining standalone players.
Upwind extended its CNAPP into AI workload security (AI-DR, AI-SPM, AI-BOM, MCP Security) relatively early and secured a marketing proof point via joint Nvidia research on prompt-injection detection precision (95%, company-disclosed). This positions the company to capture cross-sell as CNAPP budgets increasingly bleed into AI security line items.
Buy-Side Thesis Summary: Upwind’s rapid re-rating reflects three re-pricing catalysts firing simultaneously — a proven founding team, structural technical differentiation, and a well-timed competitor vacuum. Sustaining the thesis hinges on two swing factors: whether the company hits its year-end $100M ARR target, and whether it can defend share against large platform vendors (notably Palo Alto Networks’ Prisma Cloud and CrowdStrike) moving aggressively to backfill the CNAPP gap Wiz left behind.
For balance against the bull case, this section catalogs the principal risk factors evident in currently available public information — with particular attention to the valuation-to-revenue multiple, competitive re-configuration, and data-transparency limitations.
Against an unconfirmed estimated ARR of $50–60M, the $3.8B valuation implies a roughly 65x–76x ARR multiple; even applying the year-end $100M target, the multiple remains an elevated 38x. The speed of the re-rating itself — 2.5x in eight months — raises the probability of down-round pressure or multiple compression should the current re-rating cycle in cybersecurity cool.
ARR, headcount, and even round-lettering (Series A vs. B for the 2024 raise) diverge across sources, and no audited financial statements are publicly available. This is not unusual for a private growth-stage company, but it does mean self-reported growth metrics (e.g., 900% revenue growth) cannot be independently verified for underwriting purposes.
Following Wiz’s absorption into Google, Palo Alto Networks (Prisma Cloud), CrowdStrike, Orca Security, and Sysdig are all pushing harder on platform consolidation, and large vendors in particular can bundle CNAPP into existing endpoint/SIEM relationships — a distribution advantage Upwind’s standalone positioning lacks. This creates a structural pricing and channel disadvantage over the medium term.
As the CEO himself has acknowledged, customers are reluctant to install agents. An eBPF-sensor-based runtime approach may face longer initial deployment friction relative to agentless competitors, a structural risk to enterprise sales-cycle length and pilot-to-close conversion.
Core R&D headcount is concentrated in Israel, exposing the company to regional geopolitical uncertainty that could affect operations and customer confidence. That said, numerous Israeli-founded cybersecurity unicorns — Wiz included — have scaled through comparable exposure, so realized risk is roughly in line with sector norms.
Guiding from sub-$20M ARR at year-end 2025 to a $100M target by year-end 2026 requires better than 5x growth in a single year — an aggressive plan by any standard. A miss would undermine the growth narrative underpinning the current valuation and directly weaken leverage in any subsequent financing round.
Bottom Line: Upwind combines a proven founding team, structural technical differentiation, and a well-timed category vacuum left by Wiz’s exit — three genuine re-rating catalysts. The current valuation, however, remains substantially narrative- and momentum-driven, with limited audited revenue verification to date. The publication of formal financials at a subsequent financing event, M&A process, or IPO filing should be treated as the key trigger for revisiting this thesis.

